{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-54644/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CubeCart (6.7.4)","CubeCart (\u003c= 6.7.4)"],"_cs_severities":["high"],"_cs_tags":["webapps","sqli","cube-cart","xss","injection","cve-2026-54644"],"_cs_type":"threat","_cs_vendors":["CubeCart"],"content_html":"\u003cp\u003eCubeCart version 6.7.4 is affected by an authenticated SQL injection vulnerability, identified as CVE-2026-54647. The vulnerability exists within the administrative settings interface, specifically in the file \u003ccode\u003eadmin/sources/settings.index.inc.php\u003c/code\u003e. The application fails to properly sanitize the \u003ccode\u003edownload_expire\u003c/code\u003e parameter when processing POST requests to save administrative settings. Because the application uses an unsafe concatenation method to build database queries, an authenticated administrative user can inject SQL syntax by including commas and other SQL control characters in the payload. This vulnerability allows an attacker to manipulate the \u003ccode\u003eUPDATE\u003c/code\u003e SQL statements executed by the application, potentially leading to unauthorized modification of database settings or other database-level actions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid administrative credentials for the target CubeCart instance.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the CubeCart administrative dashboard.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the administrative Settings page.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a save request for the system settings.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the HTTP POST request using a proxy tool.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the \u003ccode\u003edownload_expire\u003c/code\u003e parameter to include malicious SQL syntax, such as \u0026quot;1, expire=0 WHERE 1=1-- -\u0026quot;.\u003c/li\u003e\n\u003cli\u003eThe application processes the tainted input and executes the injected SQL command against the database.\u003c/li\u003e\n\u003cli\u003eUnauthorized changes are applied to the database configuration or data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated administrative attacker to manipulate arbitrary columns within the database settings tables. This can result in unauthorized changes to system configurations or potentially facilitate lateral movement and further data compromise within the underlying database.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CubeCart to version 6.7.5 or later immediately, as this version contains the fix for CVE-2026-54647.\u003c/li\u003e\n\u003cli\u003eAudit administrative access logs for suspicious account activity that precedes configuration changes.\u003c/li\u003e\n\u003cli\u003eReview database access logs for evidence of malformed SQL queries originating from the administrative settings endpoint.\u003c/li\u003e\n\u003cli\u003eDisable or restrict access to the administrative dashboard to trusted internal IP addresses only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T14:05:17Z","date_published":"2026-08-31T14:04:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cubecart-sqli/","summary":"An authenticated SQL injection vulnerability in CubeCart 6.7.4 allows administrative users to execute arbitrary SQL commands due to improper sanitization of the download_expire parameter.","title":"SQL Injection in CubeCart 6.7.4","url":"https://feed.craftedsignal.io/briefs/2026-08-cubecart-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-54644","version":"https://jsonfeed.org/version/1.1"}